← back
CVE-2015-1805observed exploitation

CVE-2015-1805

45Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actepss 1.4%
from disclosure to weapon4028 days
Published on NVDAug 8
1st PoC+4028d
VulnCheck+223d
exploitation probability
1.4%top 30% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun."
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.